vivac
A tree where every node knows which node it was born from.
So that months later something can still answer “why are we here?”
$ vivac why 4
Why we are here -> t4
------------------------------------------------------------------
g1 Ship the 2.0 API
the first customer is waiting on it
(4 open / 1 closed below)
|
v
t2 Replace the cache adapter
the session bug traces back to it
(3 open / 1 closed below)
|
v
t4 No test for expiry [closed]
no way to reproduce the session bug
! the corpus run is what settled it
= reproduced: sessions expire at 300s, not 3600
^^^ you are here
In parallel, still open (3):
t3 Rate limiting is undecided
d5 Retry policy: three tries, then fail loudly
t6 Migrate the callers
t2 does not close until these close (1):
t6 Migrate the callersWhat you get · See it · Install · First five minutes · Why one map · Bring a project in
Built for one person's own work
I run eight projects in parallel — open source, work and my own — and five
of them are large. Every time I came back to one I had to piece together what
had been decided in it, and more than once I watched the agent change
something we had already settled, because both of us had forgotten we had.
What I had against that was manual: ending each stretch of work by asking
the model for a safepoint, so we can pick this up later, or keeping a
where_are_we.txt at the root of the project.
vivac is what replaced them, and it is still measured on those projects. That is the whole of its pedigree, and it shows in what got built: every mechanism here came out of a defect that had already cost me days, and every number on this page came off a real tree rather than a benchmark written to make a README look good.
The tree this project keeps of itself, 23 days in: 695 nodes, 315 of them closed, 176 standing decisions, 16 levels deep.
Three of those defects, and what each one turned into:
A run marked
DONEwith its findings still open — and 26 days before anybody noticed. Nowvivac donerefuses, and says what is missing.A reading list of 109 open fronts across 224 lines, with the one touched yesterday at the bottom. Now
openanswers what is waiting on you, in that order, and stops at ten.Three claims shipped to crates.io that the binary beside them contradicted. Now a test runs every command this page shows and holds its lists against
--help.
What I would not give up now is no single feature. It is looking at the tree of what was decided and why; picking a project back up with whichever model is at hand and having it know what the last one settled; and knowing where the work stands at any moment. In my experience that is worth more than anything else here, and I hope it serves you as well.
Issues are open, and I want to hear where it fails you. Pull requests are not
open yet; CONTRIBUTING.md says why.
Related MCP server: Provena
The problem
When you develop with an agentic AI, work spawns more work. Three hops in, you have lost the thread of what you originally set out to do.
It is not a memory problem: usually everything is written down. It is a provenance problem. What is written does not say what it was born from, and without that edge there is no way to reconstruct why you are where you are.
Measured on a real compiler: the path between the goal and the day's work was six levels deep, spread across a chronologically ordered 8,853-line tracker, 52 planning documents and 21 issues. The structure was temporal, which is exactly the opposite of provenance.
Logbooks, decision records, issue trackers and session memory for agents all store the node. Where one of them stores the edge as well, it is a link somebody has to remember to add — so it is missing on exactly the node where nobody thought it would matter. Where it sits goes through them category by category, and says where each one is better than this.
What you get
The agent starts oriented, and nobody has to ask it to. A hook runs
vivac session start when a session opens, so the first thing in its context
is where you are, what has already been decided, and what not to touch:
$ vivac brief
vivac · project: demo · lane: main · 2026-09-21
------------------------------------------------------------
GOAL g1 Ship the 2.0 API
|
|-- t2 Replace the cache adapter
| why: the session bug traces back to it
|
`-- t6 Migrate the callers <== HERE
why: the old adapter had a different signature
STANDING DECISIONS
d5 Retry policy: three tries, then fail loudly
LAST VIVAC
v5 · push · 2026-09-21 · bcdba21
you were about to: Migrate the callers
------------------------------------------------------------
143 tokens · depth 3 · 0 parkedIn tokens, that is the whole argument. A project keeping its state in three places was asked to pick up where it left off. A hand-written plan answered in 9,252 tokens. A memory system answered “maybe” in about 12,720, depending on which of two names for the project it resolved. The tree answered in 100. The brief carries a token budget because a context window is the one resource every session spends.
Nothing closes over what is still open. The one operation in the model that rejects, and it earns it: a run marked done over open findings took 26 days to be spotted once.
$ vivac done 2
t2 CANNOT close: 1 open closure condition(s)
t6 Migrate the callers
A run closes with its findings, not with its report.
Closing it anyway leaves a trace: vivac done 2 --forceEvery decision keeps what it turned down, and what it was judged against.
--alternative holds the option rejected, --supersedes links a reversal to
what it reverses, and --against records the rule or pillar that decided it —
so a decision can be argued with a year later instead of guessed at. This
project's own tree carries 176 of them.
An assumption that falls does not take its children with it. abandon
marks the premise refuted and everything under it goes with it, except what
you rescue — and what is rescued still hangs where it was born, because
being born somewhere is not undone by that place turning out to be wrong.
What it does not promise
It saves tokens, not all of them. Picking a project up took the tree 100 tokens where a hand-written plan took 9,252, and that difference comes back every time a session opens. The agent still reads files, still reasons and still explains itself, and none of that gets cheaper.
It does not make sure nothing is ever forgotten. No memory system can, this one included, because every one of them still runs on the model's judgement: should I save this? is this a finding? do I need to read the tree again before I answer? The best skill in the world, a hundred subagents or a hundred daemons move where that judgement happens, and none of them removes it. vivac hangs capture off the seams of the work rather than off that judgement, and still measures where it slips.
What is left over after that is why the tree is built to be looked at.
See it
vivac webThe agent writes the tree, and you can read it at any moment without asking
the agent anything. vivac web opens every project on this machine in a
browser: which one moved and which has been sitting still, what changed in
one while you were away, a node's whole lineage, and the whole tree. It is
where you see the state of each item for yourself, and where you catch what
the agent let pass.
Four example projects, written by real vivac commands with
tools/web-screenshots.py, which takes these
pictures again whenever the pages change.
A server you start and that dies when you close it, bound to 127.0.0.1,
reachable through a one-time key it prints. It has no functions of its own:
anything a page needs is built on the command line first.
→ What the web is, and is not
One map
vivac was not built to compete with memory systems. I have used engram, by Alan Buscaglia, and I contribute to it. What I set out to build was a record of decisions, and the road there turned out to need a memory; that is how vivac came to work as one, kept in a file in the project so that whichever harness or model you open it with reads the same thing. It is not a better memory system than engram or any other. It was built for something else.
That is why the advice runs both ways. If you already use a memory system and it serves you, do not add vivac. If you want vivac for the tree, do not keep another one beside it — any one. Each system injects its own context into the model, and two maps collide: each points the agent at what it holds, and sooner or later one settles something the other mapped differently, with nobody noticing which of the two oriented the decision.
That is observed, not assumed:
A written rule can create a seat no tool can read. In one project an instruction told the agent to mirror every update into its memory system. That made three seats at the table, and the one that actually governed was the only one nothing could inspect.
The harness brings its own map, whether you chose it or not. In the project that builds vivac — with everything else deliberately turned off, precisely to test whether the tree alone could carry the thread — the harness's automatic memory kept injecting a copy of the project's doctrine into every session for five days before anybody noticed. The measurement was not wrong. It was invalid, and nothing said so.
So why not just the harness?
It gives you the session. It does not give you three things, and each absence is a specific failure rather than a missing feature:
No edge. It stores what was learned, not which piece of work it came out of, so there is nothing to walk back along.
No focus. Everything recalled is equally present, and none of it says you are here — or, more to the point, do not touch that.
No open and closed state. Nothing can be reported as still missing.
And the harness's memory belongs to the harness. Change tool and the
thread does not come with you. .vivac/ is a file in your project: plain JSON
lines, exportable in one command, readable without this binary.
vivac turns nothing off, and neither does setup — another system is not vivac's to touch. What it gives you is a skill that finds every other map the agent receives and offers to retire each one, after you say yes, in a form that can be undone.
What it costs
Budgets, not aspirations: a read is given 50 ms and a write 5 ms, and where that is missed it is named rather than left out.
Measured on 18 September 2026 at ten thousand nodes, 200 calls per cell,
on two machines and at two tree shapes, because what brief and open cost
is governed by how many fronts are still open rather than by how many nodes
exist. p99 in milliseconds:
|
|
|
| |
CLI, cold process, Linux | 15.5 | 18.8 | 20.4 | 19.9 |
MCP, resident server, Linux | 0.5 | 7.1 | 4.2 | 8.8 |
A write over MCP is 0.6 ms at p99 and flat in the size of the tree. And
because context is the budget that actually binds, the payloads are measured
too: vivac_open over ten thousand nodes went from 1,993,053 bytes to
599,012, and why --json on a deep node from 86,894 to 7,139.
→ The full numbers — both machines, both tree shapes, the write table, and what Windows misses and why.
What it never stores
A provenance tree is a map of where a system is weak and not yet fixed, which forces a few things that are not negotiable:
No keys and no secrets. A redaction guard at write time. In doubt it refuses and says why; it never stores in silence.
No personal data. No email, no name, no home path. The
actoron every event is an opaque identifier.No file contents. Only paths, references and prose about what was decided — so a leak bounds to what was being worked on, never to what the code is.
No telemetry. The binary does not phone home. Ever.
These come from the pillars: security vetoes, performance budgets, UX proves a surface is worth reading, DX judges.
Install
Every release carries a
precompiled binary — Linux and macOS on x86_64 and aarch64, Windows on
x86_64 — listed in SHA256SUMS and carrying signed build provenance.
Unpack one and put vivac on your PATH.
With a Rust toolchain, 1.89 or newer:
cargo install vivaccargo install is not the fallback: it builds from the source published to
crates.io, so it stays the auditable path for anyone who cares about the
supply chain of a tool that reads their work.
To move to a newer release, run vivac update. It shows how this vivac was
installed and what replacing it takes — the cargo install that built it, or
the release archive it came from, checked against SHA256SUMS — and does it
once you answer yes. On Windows it sets the running copy aside first, so the
install does not wait for your sessions to close. With no terminal to answer
in, it only says what to type.
→ Setting it up
The first five minutes
1. In the folder you open your agent in. The first plants the tree, the second gives your agent the hooks, the server and the skill. Both show every file they will touch, and the exact command each hook will run, and then ask:
vivac init
vivac setup claude-code2. Start the first thread. You were going to say what you are doing anyway; saying it here is what creates the edge, for free:
vivac push "Replace the cache adapter" --why "the session bug traces back to it"
vivac push "No test for expiry" --why "no way to reproduce it" --blocks
vivac pop "reproduced: sessions expire at 300s, not 3600"3. Ask where you are, and why:
vivac brief where you are, and what NOT to touch
vivac why 2 the path from the root, narrated
vivac open what is waiting on you, and what has been sitting
vivac web the whole tree in a browser, on this machine onlyThat is the loop. → When each one runs, and what to say when your agent skips one · Every command
Bringing a project in
Nothing moves into vivac on its own.
If your project already keeps what it has learned — in a memory system, in
CLAUDE.md, AGENTS.md, MEMORY.md, the harness's own memory, or internal
documents — none of that is in the tree after vivac setup. vivac never
reads another system and never reads those files, because telling a rule from
the prose around it takes judgment, and a tool that guessed would fill your
tree with confident nonsense on day one.
So it is a job for the agent, with you deciding what goes in. setup installs
the vivac-migrate skill, and you say:
Use the vivac-migrate skill to bring everything this project knows into vivac.
It lists every source it finds, asks which to bring in, shows a plan before writing anything, checks what it wrote — and then offers to retire the other maps, one at a time. That last step is the point, not the tidying up: a full tree with the old records still talking to the agent is two maps, which is the state this gets you out of.
→ Bringing a project in, and what happened on real projects: eight migrations, two measured source by source, and what each failure changed.
Lanes
You work on one product from more than one folder: a checkout on main, a
second one for a hotfix, a third for reviewing somebody else's branch. Or one
folder and ten branch changes a day.
The record must not fork when the folders do. What was this born from? has one answer for the product, not one per checkout — three trees answering it three ways is three wrong answers.
So the tree belongs to the product, and every folder that works on it is a lane. The branch is a fact recorded on each write, not something the tree is kept in.
What that buys you: the brief tells you when a branch moved under you, and what the other lanes have done since you last wrote here.
Your situation | What to run |
another folder, under the same tree |
|
a folder somewhere else entirely |
|
the tree should live elsewhere |
|
which lanes exist, and what each is on |
|
Read codex for claude-code wherever you use it, including in the same
folder as the other: the harness decides which files a folder gets, and never
anything about the tree.
→ docs/LANES.md — what a lane is and is not, and the
four ways to get it wrong.
Where this is measured
Claude Code |
|
Codex |
|
Anything else | The hooks call ordinary commands. Any harness that can run one when a session opens and put its output in the agent's context can call the same one, and any MCP client can run |
One step of that walk is not measured and cannot be: approving each hook inside Codex is something a person does, once, and looking at a person is not a measurement.
Not there yet: team mode. The project is in 0.x and
breaks on the minor while it is.
Documentation
the moments of a session, who acts at each, and what to say if the agent skips one | |
every command, grouped by who runs it | |
what setup writes, Codex, the MCP server, where things are stored | |
the migration, and why it is a migration and not an addition | |
one product, several folders, one tree | |
the full measurements, and how they were taken | |
what breaks when, and what keeps | |
what each category of tool stores, and where each is better than this | |
the four arbiters every decision here is judged against |
Licence
MIT OR Apache-2.0, at the option of whoever uses it. The text of each is in
LICENSE-MIT and LICENSE-APACHE.
The licence covers the code and not the name: a fork is free, and it goes out
under a name of its own. TRADEMARKS.md says what the name
and the logo can be used for. A security flaw goes privately, as
SECURITY.md says.
Available Tools
15 toolsvivac_addFile a node without moving the focusA
File a node without touching the stack: the focus stays exactly where it was. Use it for something that belongs in the tree but is not the next thing about to happen -- a finding surfaced while working on something else, a sibling task filed for later, a piece of an existing structure being brought in. vivac_push is for what comes next; this is for what was just noticed. Look first with vivac_find: what the tree already holds is not filed twice. A finding is one node for each thing found that you tell the person, written when you tell them. One that asks nothing of anyone -- a lesson, a measurement -- is a record: close it right away with vivac_done, its outcome starting with Record:.
| Name | Required | Description | Default |
|---|---|---|---|
| arm | No | Commands that verify this rule, one per entry, all run in arm_dir. Only for a rule; a rule without one is judged. vivac never runs them. | |
| ref | No | Paths or identifiers this node is about. | |
| why | No | Why this matters. | |
| root | No | Born at the root, with no parent, instead of under the focus. Refused together with parent. | |
| type | No | goal, task, decision, question, constraint, finding, assumption, pillar or rule. Defaults to goal at the root, task otherwise. A pillar is titled with its name and what it restricts, in the project's own words. | |
| title | Yes | What this node is, in a few words. | |
| blocks | No | Its parent cannot close while this one is still open. | |
| parent | No | The node it hangs from. Defaults to the current focus, or the root if there is none. | |
| against | No | Only for a decision: a pillar or rule it was judged against and a sentence on how it holds, as one entry: "r12: the write path stays local". Repeat for each one. | |
| arm_dir | No | The folder every arm given here runs in, relative to the folder that holds .vivac: vivac, say, or . for that folder itself. Required with arm, refused without it. It has to exist. | |
| governs | No | Globs of files this node's work is expected to touch. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations disclose the safety profile (write, non-destructive, non-idempotent), so the description's job is to add context. It does: dedup constraint via vivac_find, the one-node-per-finding rule written when the person is told, and the record-closing workflow. It does not explicitly warn that a repeated call creates a duplicate node, but the dedup guidance and idempotentHint=false together convey that.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The core distinction from vivac_push is front-loaded in the first sentence and there is no filler per se, but the description is dense and runs long with several trailing workflow rules that could be tightened. Appropriately sized for an 11-parameter tool, though not maximally lean.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
No output schema exists and 11 params (1 required) give this tool real complexity, but the description covers the primary use cases, the dedup prerequisite, sibling routing, and node-creation semantics. It does not explain return values or what filing produces, which is the remaining gap.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100% across all 11 parameters, so the schema already documents every field including type, arm, ref, why, parent and governs. The description adds meaning for the 'finding' and record node concepts but no per-parameter syntax or format. Baseline 3 applies when the schema does the heavy lifting.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and effect ('File a node without touching the stack: the focus stays exactly where it was') and explicitly contrasts with the sibling vivac_push ('is for what comes next; this is for what was just noticed'). An agent can distinguish it from vivac_push, vivac_find, and vivac_done without opening any schema.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Gives explicit when-to-use cases ('a finding surfaced while working on something else, a sibling task filed for later'), names the alternative it is not (vivac_push), prescribes a prerequisite ('Look first with vivac_find: what the tree already holds is not filed twice'), and routes follow-up work to vivac_done for records. Nothing about selection is left to inference.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
vivac_armRecord the command that verifies a ruleA
Record a command that verifies a rule and the folder it runs in, or with off, remove one. vivac never runs it: it hands it to whoever checks the rule. Call it the moment a test for a rule exists, because the day a rule became checkable is part of its history.
| Name | Required | Description | Default |
|---|---|---|---|
| id | Yes | The rule, as the tree names it: r12. | |
| dir | Yes | The folder the command runs in, relative to the folder that holds .vivac: vivac, say, or . for that folder itself. It has to exist. | |
| off | No | Remove this command, in this folder, from the rule instead of adding it. | |
| command | Yes | The command or test that verifies it, as someone would type it. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare the safety profile (readOnlyHint=false, destructiveHint=false, openWorldHint=false), so the bar is lower. The description adds real value beyond that by disclosing that vivac never executes the command ('it hands it to whoever checks the rule') — a genuinely useful behavioral fact. It stops short of explaining duplicate/idempotency behavior despite idempotentHint=false.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Front-loads the core action and the off-mode in the first sentence, then adds rationale. The closing clause about 'the day a rule became checkable is part of its history' is poetic and arguably speaking to motivation rather than mechanics, but it is short and does orient the agent's intent.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a write tool with 100% schema coverage and no output schema, the description covers the add/remove duality and the non-execution behavior adequately. It leaves minor gaps around what happens on repeated calls (idempotentHint=false), but nothing an agent needs to call it correctly is missing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema already documents id, dir, command, and off. The description's mention of the 'off' removal mode and the 'folder it runs in' only restates what the schema provides, adding no new syntax or format detail. Baseline 3 is correct.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (record) and resource (a command that verifies a rule plus its folder), and explicitly covers the inverse mode ('or with off, remove one'). This is clearly distinguishable from 'declare a rule' or 'note something' siblings like vivac_declare/vivac_note.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Gives an explicit timing trigger: 'Call it the moment a test for a rule exists.' That is actionable context for when to invoke it. However, it never names an alternative tool or a when-not-to-use condition, so the sibling-routing guidance is incomplete.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
vivac_briefBrief: where you are and what not to touchARead-only
Where you are in this project and what NOT to touch right now: the focus with its lineage, the parked nodes with the reason each was parked for, the decisions that still govern, and the last safe point with what you were about to do. Read it before anything else when a session opens.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already establish read-only, non-destructive, closed-world behavior, and the description usefully goes beyond them by detailing the readout's contents (focus, parked nodes, decisions, last safe point). Since no output schema exists, this enumeration is the agent's only signal about what comes back, and it covers that burden well.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The core sentence front-loads the purpose ("Where you are ... and what NOT to touch") and the trailing sentence lands the usage instruction. It is dense but every clause maps to a distinct part of the returned brief; slightly long but not padded.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no parameters and no output schema, the description carries the return-value burden alone, and it does so by listing the four components of the brief. That is sufficient for an agent to call and interpret it, though the absence of any format or size cue leaves a minor gap.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
This is a zero-parameter tool, so there is nothing for the description to disambiguate and the baseline is 4. The description adds no misleading parameter claims.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description names a concrete deliverable – a session brief – and enumerates its parts: focus with lineage, parked nodes with reasons, governing decisions, and the last safe point. An agent immediately understands it returns a synthesized state view rather than a filtered query. It does not explicitly contrast itself with siblings like vivac_why or vivac_find, so it stops short of a 5.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
"Read it before anything else when a session opens" is an explicit, actionable usage directive that tells the agent exactly when to reach for this tool. It gives no exclusions or named alternatives, so an agent must still infer why it would choose vivac_why or vivac_find at other moments.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
vivac_decideRecord a decisionA
Record a decision, with the reason it was made and every alternative that lost. Call it the moment a choice is actually settled, not before and not long after: the alternatives are optional in the schema and not in practice, because without them the same option gets proposed again in a month by whoever was not in the room. When the project has pillars or rules, name in against the ones this was judged against, each with a sentence: a pillar judged in silence reads the same as one skipped.
| Name | Required | Description | Default |
|---|---|---|---|
| ref | No | Paths or identifiers this decision is about. | |
| root | No | Born at the root, with no parent, instead of under the focus. Refused together with parent. | |
| title | Yes | The decision, in a few words. | |
| blocks | No | Its parent cannot close while this one is still open. | |
| parent | No | The node it hangs from. Defaults to the current focus, or the root if there is none. | |
| reason | Yes | Why this and not something else. A decision with no reason is a datum, not a decision. | |
| against | No | A pillar or rule this was judged against and a sentence on how it holds, as one entry: "r12: the write path stays local". Repeat for each one. vivac checks that the pillar or rule exists and still governs; the sentence is not judged. | |
| governs | No | Globs of files this decision's work is expected to touch. | |
| supersedes | No | An earlier decision this one retires. | |
| alternative | No | An option that was ruled out. Repeat for each one. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations cover only the safety profile (readOnly=false, destructive=false, idempotent=false, openWorld=false), consistent with a write tool. The description adds behavior not in the annotations: vivac validates that each named pillar/rule 'exists and still governs' while the accompanying sentence is not judged — useful validation semantics for the `against` field. It does not discuss what happens on supersession or duplicate titles, so it isn't exhaustive.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Three sentences, front-loaded with the core action and timing rule, with the rationale ('proposed again in a month') following rather than leading. The closing line — 'a pillar judged in silence reads the same as one skipped' — is rhetorical but earns its place as a memorable rule of thumb; the surrounding prose is slightly dense but not padded.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a 10-parameter, no-output-schema write tool with 100% schema coverage, the description supplies what the schema cannot: when to call it, why the soft-required fields matter, and how the `against` entries are validated. The remaining fields (ref, root, parent, governs, supersedes) are self-documented in the schema, so nothing an agent needs to call it correctly is missing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the baseline is 3 and the schema already carries most field meaning. The description still adds real value beyond it by explaining that `alternative` is behaviorally mandatory despite being schema-optional, and by clarifying the intended content of `against` (a pillar id plus one sentence on how it holds).
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description opens with a specific verb+resource: 'Record a decision, with the reason it was made and every alternative that lost.' That is unambiguous and tells an agent exactly what artifact gets produced, and the 'decision vs datum' framing subtly separates it from a plain note tool. It stops short of naming which sibling to prefer (vivac_note, vivac_declare), so a 4 rather than a 5.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It gives an explicit timing rule — 'the moment a choice is actually settled, not before and not long after' — plus the operative constraint that alternatives are 'optional in the schema and not in practice,' with the consequence spelled out (the same option gets re-proposed in a month). This is exactly the when-to-use guidance an agent needs, including the counter-intuitive case where a schema-optional field is effectively required.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
vivac_declareRecord what a decision was judged againstA
Record, after the fact, the pillars or rules a decision was judged against, each with a sentence. Call it the moment the judging happens -- someone asks whether a decision holds against a rule, and it gets checked -- because when a decision was judged is part of its history, and this one shows as late. It only adds to a decision that already exists, and declaring the same rule again replaces its sentence. A new decision takes what it was judged against when it is recorded, through vivac_decide; vivac_rules lists the pillars and rules there are.
| Name | Required | Description | Default |
|---|---|---|---|
| id | Yes | The decision, as the tree names it: d12. | |
| against | Yes | A pillar or rule it was judged against and a sentence on how it holds, as one entry: "r12: the write path stays local". Repeat for each one. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare this is a non-read-only, non-destructive write. The description adds behavioral detail beyond that: it only augments an existing decision (no creation), re-declaring the same rule replaces its sentence, and the judgment is timestamped as 'late' in the decision's history. It does not say what happens if the id does not exist, which is the notable gap.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The core purpose is front-loaded in the first clause, which is good. However the 'Call it the moment the judging happens -- someone asks whether a decision holds...' sentence is atmospheric narration that conveys little operational information and could be compressed to 'records the judgment after the fact, so it shows as late in history'. Middle section is bloated relative to the payload.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a 2-parameter tool with full schema coverage and no output schema, the description covers purpose, scope, sibling routing, and update semantics adequately. The main omission is failure behavior when the referenced decision does not exist, plus no mention of how the declaration surfaces in other views.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so both `id` and `against` are already documented with concrete formats ('d12', '
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific action (record, after the fact, the pillars or rules a decision was judged against, each with a sentence) and immediately scopes it to decisions that already exist. An agent can tell this is an additive annotation of existing decisions rather than creation. The 'moment the judging happens' framing adds some color but the operational purpose is clear.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It routes explicitly: new decisions take their judging context through `vivac_decide`, and `vivac_rules` is named as the source of the pillars/rules to reference. That gives real when-this-vs-that guidance for two siblings. It stops short of enumerating all alternatives, but the key routing decisions are covered.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
vivac_doneClose a node that is not the focusA
Close a node that is not the focus, recording what came of it. Call it right after writing a lesson or a measurement that asks nothing of anyone -- a record, whose outcome starts with Record: -- and for work that was finished somewhere else. It never closes over open closure conditions; that takes vivac done --force at a terminal, with a person looking. vivac_pop closes the focus.
| Name | Required | Description | Default |
|---|---|---|---|
| id | Yes | The node to close, as the tree names it: f12, t4. | |
| outcome | No | What came of it. For a record, what it records, starting with Record:. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations only declare the safety profile (readOnly=false, destructive=false, idempotent=false); the description adds real behavioral context beyond them: a guard that refuses to close over open closure conditions, the terminal-only '--force' escape hatch, and the human-visibility requirement. It stops short of saying what happens to a partially-resolved node's remaining data.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Three compact sentences, front-loaded with the action, then the trigger condition, then the guard and alternative. Efficient, though the dense domain vocabulary ('closure conditions,' 'a record, whose outcome starts with Record:') makes it read as compressed rather than clean.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With only 2 parameters, full schema coverage, and no output schema, the description covers the action, trigger, guard, and alternative to vivac_pop. What is missing is the failure/return behavior when the closure guard blocks the call, which an agent would benefit from knowing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so both 'id' and 'outcome' are already documented by the schema. The description reinforces the Record: prefix convention for outcome but adds no syntax or format detail beyond what the schema provides; baseline 3 applies.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb+resource: 'close a node that is not the focus, recording what came of it,' and explicitly contrasts with 'vivac_pop closes the focus.' The scope term 'not the focus' is domain jargon that assumes familiarity, but the core action and its sibling boundary are identifiable.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Gives concrete invocation conditions ('right after writing a lesson or a measurement that asks nothing of anyone... or work that was finished somewhere else') and a when-not ('never closes over open closure conditions'). It routes the agent to vivac_pop for the focus case but does not enumerate how other siblings (e.g. vivac_add, vivac_push) differ.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
vivac_findFind nodes by their wordsARead-only
Search the provenance tree. Returns every node whose title, reason, note or outcome contains all of the terms, best first, each with the lineage it hangs from. Ranking is not recency: a hit in the title outranks a hit in a note, a node holding up more tree outranks one holding up less, and recency is only the last tiebreak. Closed nodes are included: what you look for months later is usually finished.
| Name | Required | Description | Default |
|---|---|---|---|
| query | Yes | Words to look for. Every one of them has to appear. | |
| everywhere | No | Searches every project on the machine rather than this one. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already establish read-only, non-destructive, closed-world behavior, so the description does not need to restate safety. It goes further by disclosing the ranking algorithm (title > note, node supporting more tree ranks higher, recency last) and that each result carries its lineage — genuinely useful traits not present in the annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Four sentences, front-loaded with the core action and filtering rule, then ranking, then the closed-node caveat. Mostly earns its space, though 'what you look for months later is usually finished' is slightly rhetorical padding.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no output schema, the description carries the return-value burden and does so: it promises all matching nodes, best-first, each with its lineage. Ranking rules and the closed-node inclusion policy complete the picture an agent needs to interpret results.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so baseline is 3, but the description adds real semantics beyond the schema: matching is conjunctive across title/reason/note/outcome, which tells the agent to expect zero results for loose multi-word queries. The 'everywhere' flag's effect is left to the schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and resource ('Search the provenance tree') and immediately scopes what is matched: nodes whose title, reason, note or outcome contains ALL terms. That distinguishes it from sibling read tools like vivac_why or vivac_brief, which serve different retrieval intents.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Usage is implied rather than stated: 'what you look for months later is usually finished' signals the case where closed nodes matter, and the ranking note hints at search-vs-browse. But no sibling is named as an alternative and no when-not-to-use condition is given, so an agent must infer routing among the 14 vivac_* tools.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
vivac_noteAttach a fact to a nodeA
Attach a fact to a node without changing its state or the stack: something worth keeping that is not itself a new node. Call it beside vivac_push and vivac_pop for anything that would otherwise only live in a chat transcript nobody rereads. When the fact deserves to be found on its own -- a finding, a measurement -- file it as a node with vivac_add instead.
| Name | Required | Description | Default |
|---|---|---|---|
| id | No | The node to attach it to. Defaults to the current focus. | |
| note | Yes | The fact to attach. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already disclose the mutation profile (readOnlyHint=false, destructiveHint=false, idempotentHint=false), and the description adds real value beyond them: the note does not alter node state or the stack, and it is not itself a node. It does not address what happens on repeated calls despite idempotentHint=false, which is a minor remaining gap.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Front-loaded with the core action, then routing to siblings; roughly three tight clauses with no wasted preamble. The aside 'nobody rereads' is rhetorical flavor that slightly dilutes the density but does not obscure the instruction.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
A two-parameter, no-output tool with full schema coverage and annotations present; the description supplies the decision logic an agent needs (note vs. push/pop vs. add) and the non-mutating guarantee. Only the repeat-call/visibility behavior of notes is left unstated, which is a minor omission.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%: the id parameter's 'Defaults to the current focus' and note's 'The fact to attach' are already documented in the schema. The description adds no syntax, format, or length guidance beyond that, so the baseline of 3 applies.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and resource ('Attach a fact to a node') and immediately delimits the scope ('without changing its state or the stack'). It explicitly distinguishes itself from vivac_push, vivac_pop, and vivac_add, so an agent can route without opening sibling schemas.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Gives a positive use case (facts that would otherwise only live in a chat transcript, called alongside vivac_push/vivac_pop) and an explicit exclusion with a named alternative: if the fact 'deserves to be found on its own -- a finding, a measurement' use vivac_add. Both when-to-use and when-not are stated.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
vivac_openList the open frontsARead-only
List what is still unfinished in this project: every open node with nothing open under it, the ones that block their parent first, then those holding up the most tree, then the newest. Each comes back as its alias, kind, state, title and the aliases above it; vivac_why on an alias brings the rest. Use it to answer what is left or what is waiting. For where this session stands, read vivac_brief; to look for something by its words, vivac_find.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true and destructiveHint=false, so the safety profile is covered. The description adds genuine behavioral detail beyond that: the sort order (blockers first, then most-blocking, then newest), the returned fields (alias, kind, state, title, ancestors), and the handoff to vivac_why for more. It doesn't mention output size or pagination behavior, keeping it short of a 5.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Front-loaded with the core purpose, and each subsequent clause adds real information (selection rule, ordering, return shape, routing). The ordering clause is dense and slightly cryptic ('holding up the most tree'), but nothing is padding.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no output schema, the description must carry the return value, and it does: alias, kind, state, title and the ancestor aliases, plus a pointer to vivac_why. Combined with annotations covering safety and zero parameters, an agent has everything needed to call and interpret this tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The tool takes zero parameters, so the baseline is 4 and there is no parameter meaning to add. The description correctly avoids implying any filters or options.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb+resource ('List what is still unfinished in this project') and goes further by defining the exact selection rule: nodes with nothing open under them. It then distinguishes itself from siblings by naming vivac_brief and vivac_find, so an agent can route correctly without reading other schemas.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Explicitly states its purpose ('Use it to answer what is left or what is waiting') and names the alternatives with the condition that selects them: vivac_brief for session state, vivac_find for word-based lookup. When-to-use and when-to-use-something-else are both covered.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
vivac_parkPark a node: not nowA
Suspend a node without abandoning it: it drops off the stack and becomes something a later session is told not to touch. Call it when the person says not now, or when work is stuck on something outside this session -- never as a substitute for vivac_pop on something that is simply finished. What is put off has to be a node first: if it is not in the tree yet, file it with vivac_add and park that.
| Name | Required | Description | Default |
|---|---|---|---|
| id | No | The node to park. Defaults to the current focus. | |
| reason | No | Why it waits: the person's own words when they said not now. Read back verbatim under DO NOT TOUCH NOW. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations only state the safety profile (not read-only, not destructive, not idempotent), so the description contributes real behavioral information: the node leaves the stack and is later flagged as untouchable, and the reason string is read back verbatim under a DO NOT TOUCH NOW label. It does not say how a parked node is resumed or whether parking is reversible, which leaves one meaningful gap for a state-mutating tool.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The action and its effect are front-loaded in the first clause, and the remaining sentences each carry distinct information (triggers, exclusion, precondition). Slightly conversational phrasing ('something a later session is told not to touch') costs a little density but does not obscure the instruction.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
No output schema exists, so the description needs to convey what happens on success, and it does: the node leaves the stack and is marked do-not-touch. Combined with annotations covering the safety profile and near-complete parameter docs, an agent has what it needs to invoke this correctly; only the reverse operation (how to resume) is unaddressed.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so both parameters are documented structurally, and the schema already covers the default-to-current-focus behavior and the reason field's rendering. The description still adds a semantic constraint beyond the schema: the id must reference a node already in the tree, otherwise vivac_add is required first.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
Names a specific verb and resource (park a node) and states the distinctive effect: it drops off the stack and becomes something a later session is told not to touch. It explicitly distinguishes itself from the closest sibling, vivac_pop, which is a parenthetical rather than a definitional detail.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Gives explicit trigger conditions ('when the person says not now, or when work is stuck on something outside this session') and an explicit exclusion ('never as a substitute for vivac_pop on something that is simply finished'). It also supplies the precondition workflow: if the node isn't in the tree yet, file it with vivac_add first.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
vivac_popClose the focus and step backA
Close the current focus and step back to its parent, recording what came of it. Call it once the work vivac_push opened is actually finished, not on a whim to clear the stack: a node with open closure conditions refuses to close on its own, because a run that closes with its findings still open is exactly the mistake that refusal exists to catch. It steps back to the parent: if the work also settles that node -- the finding it fixed, the question it answered -- pop again.
| Name | Required | Description | Default |
|---|---|---|---|
| next | No | What comes after, when it differs from the outcome. | |
| force | No | Close anyway, over open closure conditions. Leaves a trace that it happened. | |
| outcome | No | What happened. Read back later, so leaving it out costs the next reader the point of the node. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations declare readOnly=false, destructive=false, idempotent=false, but the description adds behavior annotations cannot express: a node with open closure conditions refuses to close, and the tool steps back to its parent. That refusal/guard semantics is genuinely new context. It stops short of saying what the recording produces or how the parent transition behaves on force.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Front-loaded with the action in the opening clause, and nearly every sentence does work (when to call, misuse warning, recursion). The prose is somewhat ornate ('the mistake that refusal exists to catch'), which costs a little density but stays within a reasonable size for a guarded mutation.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
No output schema exists, so the description must carry the behavior, and it covers triggering condition, refusal guard, and recursive stepping well. It leaves unstated what a successful close returns or how force interacts with the trace, which is a minor gap for a non-idempotent mutation.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema already fully documents next, force, and outcome. The description only gestures at recording ('recording what came of it'), adding no syntax, format, or default guidance beyond the schema. Baseline 3 applies.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The first sentence names a specific verb and resource ('Close the current focus and step back to its parent, recording what came of it') and ties the tool to the sibling vivac_push, so an agent can distinguish pop from push without opening either schema. The domain vocabulary ('focus', 'node') is consistent with the sibling naming.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It states exactly when to call it ('once the work vivac_push opened is actually finished'), explicitly rules out a misuse ('not on a whim to clear the stack'), and even gives recursive guidance ('if the work also settles that node ... pop again'). Alternative-condition routing is explicit rather than inferred.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
vivac_pushOpen a node and step into itA
Open a node and step into it: it becomes the focus, and everything captured next hangs from it until a matching pop. Call it the moment a new line of work starts or forks away from the current one -- a question that has to be settled before continuing, a detour worth its own trace -- never after the fact, once the reason for taking it has already faded. Look first with vivac_find: work the tree already holds goes under its node, never into a second one. The focus is wherever work was left, perhaps by another session and about something else, so name in parent the node this work continues, or pass root when it continues nothing. why is mandatory: a detour with no reason recorded is the failure this tree exists to catch.
| Name | Required | Description | Default |
|---|---|---|---|
| arm | No | Commands that verify this rule, one per entry, all run in arm_dir. Only for a rule; a rule without one is judged. vivac never runs them. | |
| ref | No | Paths or identifiers this node is about. | |
| why | Yes | Why this is happening now. A detour with no reason is what this field exists to prevent. | |
| root | No | Born at the root, with no parent, instead of under the focus. The stack is left holding only the new node; nothing on it is closed, and the answer says how to get back. Refused together with parent. | |
| type | No | goal, task, decision, question, constraint, finding, assumption, pillar or rule. Defaults to goal at the root, task otherwise. A pillar is titled with its name and what it restricts, in the project's own words. | |
| title | Yes | What this node is, in a few words. | |
| blocks | No | Its parent cannot close while this one is still open. | |
| parent | No | The node this work continues, when it is not the focus. The stack is rebuilt as that node's path, the way vivac focus does, and the new node opens under it; the answer says what left the stack. Refused together with root, and on a node that is closed or parked. | |
| against | No | Only for a decision: a pillar or rule it was judged against and a sentence on how it holds, as one entry: "r12: the write path stays local". Repeat for each one. | |
| arm_dir | No | The folder every arm given here runs in, relative to the folder that holds .vivac: vivac, say, or . for that folder itself. Required with arm, refused without it. It has to exist. | |
| governs | No | Globs of files this node's work is expected to touch. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations declare this is a non-idempotent mutation that is not destructive; the description adds substantial behavior beyond that: the stack push semantics, the requirement that it be matched by a pop, the root-vs-focus targeting, and the mandatory `why`. It stops short of describing permissions or failure modes on a closed/parked node (those live in the schema), so a 4 rather than 5.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Front-loaded with the core action and structured as action -> when -> routing -> params. Four dense sentences with some evocative framing ('a detour worth its own trace', 'once the reason... has already faded') that costs a little efficiency but earns its place by motivating the tool's constraints.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For an 11-parameter mutation tool with no output schema but 100% schema description coverage, the description supplies the mental model (focus stack, matching pop, parent/root targeting) an agent needs. Remaining gaps (exact refusal conditions, return payload) are adequately covered by the schema, so it is complete enough.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so the baseline is 3, but the description adds real value on the two most decision-critical params: `parent` names the node this work continues (or `root` when it continues nothing) and `why` is called out as mandatory. These reinforce the mutual exclusion and the required field beyond the raw schema text.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb+resource with precise scope: 'Open a node and step into it: it becomes the focus, and everything captured next hangs from it until a matching pop.' This clearly separates it from siblings like vivac_pop (the matching counterpart), vivac_find (lookup) and vivac_open.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Gives explicit when-to-use ('the moment a new line of work starts or forks away'), when-not ('never after the fact, once the reason... has already faded'), and names the alternative 'Look first with `vivac_find`' with the condition that selects it. Nothing is left to inference.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
vivac_rulesPillars, rules and invariantsARead-only
What governs this project: every pillar, the rules under each pillar and those without one, and the invariants. A pillar's title names it and says what it rejects, in the project's own words. Each rule carries the commands that verify it, each with the folder it runs in, relative to the folder that holds .vivac, or none, which means it is judged. Run a command from its folder: from anywhere else it can pass without checking anything. Read it whenever you are asked to check work against the project's rules, whether or not they arrived when the session opened: vivac hands you the rules and the commands, and the judging is yours. If it comes back with no pillar and no rule while the project keeps its rules in files such as CLAUDE.md or AGENTS.md, propose which are pillars and which are rules, let the person decide, and write them with vivac_add.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already establish read-only, non-destructive, closed-world behavior. The description adds genuinely non-obvious operational context: commands are folder-relative to the folder holding .vivac, running them elsewhere 'can pass without checking anything,' and the tool only supplies rules while 'the judging is yours.' It stops short of describing volume or pagination.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Front-loaded with the payload ('What governs this project: ...') and free of filler sentences. Some clauses are densely nested ('each with the folder it runs in, relative to the folder that holds .vivac, or none, which means it is judged'), which costs a little readability but the length is justified for a no-parameter tool whose return shape has no output schema.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no output schema, the description carries the full burden and does: it describes the return shape, the field meanings, the empty-result case, the consumption caveat, and the follow-up action. Nothing an agent needs in order to call and use this correctly appears to be missing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Zero parameters, so per the rubric the baseline is 4 and there is nothing for the description to add or omit. The schema is trivially complete.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific resource and enumerates its contents: pillars, rules under them, rules without a pillar, and invariants. It also describes the internal structure of each element (title says what a pillar rejects, rules carry verifying commands). It does not name or contrast any sibling tool (e.g. vivac_brief, vivac_declare), so differentiation is left to the caller.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Gives an explicit trigger: 'Read it whenever you are asked to check work against the project's rules, whether or not they arrived when the session opened.' It also covers the alternative path for the empty case, routing the agent to vivac_add with a concrete procedure (propose pillars/rules, let the person decide, write them).
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
vivac_saveRecord a safe stopA
Record a safe stop: a label for this point and what was about to happen next. Each call adds a new stop and never replaces an earlier one, and it neither moves the focus nor closes anything. The latest stop is what vivac_brief shows as the last one, so a session that picks the thread back up -- this one later, or someone else's -- starts where this one left off instead of guessing from the log. Call it at a clean seam: before the session ends, before a long pause or a handoff, or when the person asks for a safe point. To set a node aside, vivac_park; to keep a fact on one, vivac_note.
| Name | Required | Description | Default |
|---|---|---|---|
| next | No | What was about to happen next. | |
| label | No | A short name for this stop. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Beyond the annotations, the description explains that each call appends a new stop, never replaces an earlier one, and does not move focus or close anything. It also describes the downstream effect on vivac_brief and how future sessions resume, which is valuable behavioral context.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is front-loaded with the core action and parameter meaning, then adds behavioral and usage context in a logical order. Every sentence contributes either behavior, call timing, or sibling routing guidance.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a non-destructive append-style tool with annotations covering safety hints and no output schema, the description supplies purpose, behavior, usage conditions, and alternatives. Nothing essential for correct invocation appears to be missing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so both parameters are already documented in the input schema. The description restates the label and next-step meaning but does not add syntax, formatting, or additional semantic detail beyond what the schema provides.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific action and resource: recording a safe stop with a label and next-step note. It distinguishes the tool from siblings by naming vivac_park and vivac_note for adjacent needs, so an agent can tell what this tool is for without opening the schema.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It gives explicit call conditions: before a session ends, before a long pause or handoff, or when the person asks for a safe point. It also names alternatives and their purposes: vivac_park to set a node aside and vivac_note to keep a fact on one.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
vivac_whyWhy a node existsARead-only
Why a node exists: the chain from the goal down to it, what is open in parallel, what was born from it, and what blocks it from closing. This is the question the whole tool exists to answer. Open siblings and children are capped at eight each, every blocking one kept; full lists them all.
| Name | Required | Description | Default |
|---|---|---|---|
| id | Yes | The node as the tree names it: g1, t12, f74, d29. | |
| full | No | Every sibling and every child still open, not only the eight the answer keeps, plus each step's anchor, standing decisions and what was open at the time: what vivac why --full prints. Refused together with project. | |
| project | No | Opens a node that lives in another tree: a project name from `vivac_find`'s `everywhere`, since an alias only means something inside its own tree. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already establish readOnlyHint=true and destructiveHint=false, so safety is covered. The description adds real behavioral detail beyond the annotations: results are truncated to eight open siblings and eight open children, every blocking item is retained, and full lifts the caps. That truncation behavior is valuable for interpreting results.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Three sentences, front-loaded with the purpose and the composition of the answer, with the cap behavior last where it belongs. The line 'This is the question the whole tool exists to answer' is partly rhetorical and does not encode new facts, keeping it just short of a 5.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no output schema, the description carries the burden of describing the return, and it does: the goal-to-node chain, parallel-open items, descendants, blockers, and the eight-item caps. For a read-only query tool this is nearly sufficient; only explicit sibling differentiation is missing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so the schema already documents id, full, and project, and the description largely restates the eight-item cap that the schema's full description already mentions. It adds the 'every blocking one kept' rule, a minor increment, so the baseline 3 for schema-driven parameters is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific capability with concrete scope: the chain from goal to node, parallel-open items, descendants, and blockers. It reads as a distinct 'explain a node's rationale' tool. It does not explicitly name a sibling (brief, open, find) it differs from, so it stops short of a 5.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It asserts 'This is the question the whole tool exists to answer,' implying this is the canonical rationale query, and it enables deeper retrieval via full. But there is no explicit when-to-use/when-not, no routing against vivac_brief or vivac_open, and no stated prerequisites, so usage is only implied.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
15 tool updates
v0.17.1- First observed
vivac_add - First observed
vivac_arm - First observed
vivac_brief - First observed
vivac_decide - First observed
vivac_declare - First observed
vivac_done - First observed
vivac_find - First observed
vivac_note - First observed
vivac_open - First observed
vivac_park - First observed
vivac_pop - First observed
vivac_push - First observed
vivac_rules - First observed
vivac_save - First observed
vivac_why
TDQS
Scored across 15 tools
Most tools have clearly distinct purposes, with the descriptions explicitly contrasting related operations like vivac_pop vs vivac_done, vivac_push vs vivac_add, and vivac_note vs vivac_add. Still, the dense conceptual overlap among close/suspend/save/add/decide/declare tools means a new agent could momentarily confuse a few boundaries. The descriptions resolve these well, but the set is not perfectly unambiguous at first glance.
Every tool uses the same vivac_ prefix followed by a single lowercase word, with no mixing of camelCase, snake_case, or inconsistent verb styles. Although not all names are verb_noun phrases, the convention is completely predictable across the set. The naming is consistent and readable.
With 15 tools, the server sits at the upper end of the ideal range but each tool maps to a distinct operation in the provenance-tree workflow. No tool feels redundant or trivial, and the count is well matched to the complexity of project memory, rules, decisions, and lifecycle management. The set is well-scoped.
The surface covers the core lifecycle: session briefing, search, reasoning inspection, open-item listing, rules, push/pop/done/park/save, and recording decisions, notes, commands, and declared judgments. Minor gaps remain, such as no obvious way to edit or delete an existing node's title, reason, or outcome, though the append-only design may make these intentional. Overall, agents have a robust workaround-compatible surface.
Maintenance
Related MCP Connectors
Art provenance intelligence — 282K-node knowledge graph with cited answers and honest gaps.
Cross-agent artifact workspace with provenance across Claude Code, Codex, Cursor, LangGraph.
Human Lineage MCP server — search and query the public genealogical graph of all humanity
- memoricOAuthio.memoric
Provenance-first database for teams and agents: every value carries sources, rules and coverage.
Related MCP Servers
- AlicenseBqualityDmaintenanceVerifiable agent-to-agent task handoff with signed provenance chain.574 PyPIMIT
- AlicenseNot gradedqualityDmaintenanceEnables tracking and querying the provenance of AI-generated code, showing which sources influenced each line of code.MIT

markovian-mcpofficial
AlicenseAqualityDmaintenanceBitcoin-anchored provenance for AI outputs; enables stamping, verifying, and tracing outputs with offline-verifiable canonical roots.3Apache 2.0- AlicenseNot gradedqualityAmaintenanceA tree whose vocabulary, rules and solvers are data, edited at runtime through generic tree_* tools. Rules go red on the node that breaks them, so it works as a design-dexision ledger on any checked knowledge base.Apache 2.0